Website & forum behaviors

Nostalrius official announcements

Website & forum behaviors

by Viper » Wed Mar 16, 2016 7:55 pm

Greetings,

As the security of our players remains a priority for us, we are now investigating the source of compromised accounts, number of which has increased in the last few days. The result is that our systems are still safe and working as intended. Our logs however show multiple attempts to login on our website with wrong credentials. While the investigation is still ongoing, we decided to share with you the results so far and what you can do to protect your account, as well as what has been done on our side.

Image

It appears that these "brute force" login attempts were not made with a random username / password combination, since the "hackers" can not simply guess a complex passwords of 7 letters or more: it would take them few years for even a single account. We believe that at least one well known private server had in the past (and possibly still has?) security issues resulting in the passwords of thousands of accounts being leaked. The bad guys are simply trying these passwords on Nostalrius Begins and that is how dozens of accounts got compromised.

This is why we will repeat once again the rules for choosing a good password to keep yourself safe:
- use a unique and complicated password with at least 7 characters but no more than 16, including at least one letter, one number and if possible, one symbol
- never use a password you are already using somewhere else - this is especially true for other private servers, which sometimes are not really well secure
- your password is not easily guessed, in essence not an every-day word in any common language

On our side, we have taken the following actions:
- the number of possible login attempts has been drastically reduced to 1 per minute
- it is only possible to login on the website from your last in-game IP-address. We took this decision because it should not affect a lot of players, and will make these kind of attacks more difficult in the future

Furthermore, all the attempts to gain from these hacks have been traced and the corresponding accounts banned. These hacked accounts are usually used to gather gold that is then sold for real money. Be aware that buying gold on Nostalrius for real money will lead to an account closure. As we detect new ways to avoid our Gold Detetor, we update it and run it again on previous actions of each account. If you already bought gold once, you might get away with today but end up with your account permanently banned next week or even months down the line.

Best regards,
Nostalrius Begins
User avatar
Viper
Administrator
Administrator
 

Re: Website & forum behaviors

by Eligius » Wed Mar 16, 2016 7:58 pm

Thank you for adressing this issue
Be weary of what you download everyone..


- it is only possible to login on the website from your last in-game IP-address. We took this decision because it should not affect a lot of players, and will make these kind of attacks more difficult in the future


What if I play in a unusual place (like a cybercafe or something) and when I come home I find that my account has changed. I can not login to the website to reset my password? What if I have dynamic IP or use VPN?
Last edited by Eligius on Wed Mar 16, 2016 8:05 pm, edited 4 times in total.
User avatar
Eligius
Senior Sergeant
Senior Sergeant
 

Re: Website & forum behaviors

by Nelythia » Wed Mar 16, 2016 8:00 pm

Glad you are investigating the increased amount of compromised accounts.

Good luck figuring out.
Nelythia - 60 Warrior
Naulii - 60 Warrior

Thanks everyone for playing on Nostalrius, it was the best WoW experience in a long time.
Nelythia
Sergeant Major
Sergeant Major
 

Re: Website & forum behaviors

by Mimma » Wed Mar 16, 2016 8:02 pm

Could you - if possible - post the name of the suspected private server in question? This would indeed help other people to know if they are in any immediate risk.
Image
User avatar
Mimma
Legionnaire
Legionnaire
 

Re: Website & forum behaviors

by Diametra » Wed Mar 16, 2016 8:03 pm

Oh ok. That IP address thing is not gong to be received well by some, but it's admittedly a strong approach. I'm pleased that staff got on this and made some moves to secure us for now.
User avatar
Diametra
Knight-Lieutenant
Knight-Lieutenant
 

Re: Website & forum behaviors

by theemus » Wed Mar 16, 2016 8:05 pm

The admin of the now closed Scriptcraft private servers posted the database for the SC1 server in a publicly accessible spot. If you had an account on this server your account name as well as your password hash are out there so don't use the same info here.
theemus
Private
Private
 

Re: Website & forum behaviors

by bobmasculo » Wed Mar 16, 2016 8:06 pm

How can i change my password?
bobmasculo
Sergeant
Sergeant
 

Re: Website & forum behaviors

by Pottu » Wed Mar 16, 2016 8:08 pm

Go to:
https://en.nostalrius.org/login

Type in your account name but leave password empty. Then click "Forgot your password?" text. Follow the instructions in the email you receive. You could add [email protected] to your email contacts.

The GM team.
User avatar
Pottu
Game Master
Game Master
 

Re: Website & forum behaviors

by Nelythia » Wed Mar 16, 2016 8:08 pm

You can also go directly to https://en.nostalrius.org/password
Nelythia - 60 Warrior
Naulii - 60 Warrior

Thanks everyone for playing on Nostalrius, it was the best WoW experience in a long time.
Nelythia
Sergeant Major
Sergeant Major
 

Re: Website & forum behaviors

by Momoh » Wed Mar 16, 2016 8:10 pm

Excellent news!
Melodyx
Momoh
Sergeant Major
Sergeant Major
 

Next

Return to Announcements